Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Pan Os HIGH 8.8
CVE-2020-1975

Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary…

Fix: 8.1.12 / 9.0.6+
Fix from $1,950 2020-02-12
Nunit HIGH 8.8
CVE-2020-2115

Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.25
Fix from $1,950 2020-02-12
Fitnesse HIGH 8.8
CVE-2020-2120

Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.30
Fix from $1,950 2020-02-12
Owncloud CRITICAL 9.8
CVE-2014-2052

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of s…

Fix: 5.0.15 / 6.0.2+
Fix from $2,300 2020-02-11
Opwebapiplugin CRITICAL 9.8
CVE-2013-4334

opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities

Patch available
Fix from $2,300 2020-02-07
Checkstyle MEDIUM 5.3
CVE-2019-10782

All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-20…

Fix: 8.29+
Fix from $1,600 2020-01-30
Websphere Deployer HIGH 7.6
CVE-2020-2108

Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Jo…

Fix: after 1.6.1
Fix from $1,950 2020-01-29
Security Access Manager HIGH 7.1
CVE-2019-4707

IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attac…

Mitigation only
Fix from $1,950 2020-01-28
Openpne CRITICAL 9.1
CVE-2013-4333

OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability

Patch available
Fix from $2,300 2020-01-24
Cloudbees HIGH 7.5
CVE-2015-1809

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files …

Fix: 1.596.1 / 1.600+
Fix from $1,950 2020-01-15
Cloudbees HIGH 7.5
CVE-2015-1811

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files …

Fix: 1.596.1 / 1.600+
Fix from $1,950 2020-01-15
Idetalk HIGH 7.5
CVE-2019-18412

JetBrains IDETalk plugin before version 193.4099.10 allows XXE

Fix: 193.4099.10+
Fix from $1,950 2020-01-15
Robot Framework HIGH 8.8
CVE-2020-2092

Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with …

Fix: after 2.0.0
Fix from $1,950 2020-01-15
Pyamf HIGH 7.1
CVE-2015-8549

XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a craf…

Fix: 0.8.0+
Fix from $1,950 2020-01-15
Open Xchange Appsuite HIGH 7.8
CVE-2014-5238

XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read …

Fix: after 7.4.1
Fix from $1,950 2020-01-14
Yet Another Java Service Wrapper CRITICAL 9.1
CVE-2020-6958

An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to …

No fix yet
Fix from $2,300 2020-01-14
Firefox MEDIUM 6.5
CVE-2019-17020

If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied …

Fix: 72.0+
Fix from $1,600 2020-01-08
Rsa Authentication Manager MEDIUM 6.5
CVE-2019-3768

RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potent…

Fix: 8.4+
Fix from $1,600 2020-01-03
Easy Xml Editor HIGH 8.1
CVE-2019-19031EPSS 5%

Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The …

Fix: after 1.7.8
Fix from $1,950 2019-12-30
Xmlblueprint HIGH 8.1
CVE-2019-19032

XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The co…

Fix: after 16.191112
Fix from $1,950 2019-12-30
Xiunobbs HIGH 7.5
CVE-2019-19998

Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.

No fix yet
Fix from $1,950 2019-12-26
Restlet HIGH 7.5
CVE-2012-2656

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive informa…

Patch available
Fix from $1,950 2019-12-18
Maven HIGH 8.1
CVE-2019-16549

Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-m…

Fix: after 0.16.1
Fix from $1,950 2019-12-17
Jersey HIGH 7.5
CVE-2014-3643

jersey: XXE via parameter entities not disabled by the jersey SAX parser

Mitigation only
Fix from $1,950 2019-12-15
Modoboa Dmarc HIGH 7.5
CVE-2019-19702

The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…

No fix yet
Fix from $1,950 2019-12-10
Remedy Smart Reporting MEDIUM 6.5
CVE-2019-11216

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attack…

Fix: after 19.02.01
Fix from $1,600 2019-12-04
Olingo MEDIUM 5.5
CVE-2019-17554EPSS 12%

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Requ…

Fix: after 4.6.0
Fix from $1,600 2019-12-04
Ofbiz HIGH 7.5
CVE-2011-3600EPSS 16%

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exe…

Fix: after 16.11.04
Fix from $1,950 2019-11-26
Nifi MEDIUM 6.5
CVE-2019-10080

The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML f…

Fix: after 1.9.2
Fix from $1,600 2019-11-19
Operations Agent MEDIUM 6.5
CVE-2019-17085

XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerab…

Mitigation only
Fix from $1,600 2019-11-18